CVE-2024-2626
published 2024-03-20CVE-2024-2626: Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.73%
50.6th percentile
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 123.0.6312.86-1~deb12u1 | 123.0.6312.86-1~deb12u1 |
| chromium | chromium | >= 0 < 123.0.6312.58-1 | 123.0.6312.58-1 |
| chromium | chromium | >= 0 < 123.0.6312.58-1 | 123.0.6312.58-1 |
| debian | chromium | < chromium 123.0.6312.86-1~deb12u1 (bookworm) | chromium 123.0.6312.86-1~deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 123.0.6312.58 | 123.0.6312.58 | |
| chrome | >= 123.0.6312.58 < 123.0.6312.58 | 123.0.6312.58 | |
| chrome_chrome | — | — | |
| linux | linux_kernel | >= 0 < 6.1.119-1 | 6.1.119-1 |
| linux | linux_kernel | >= 0 < 6.11.7-1 | 6.11.7-1 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2024-2626
vendor_chrome·2024-03-19·CVSS 6.5
CVE-2024-2626 [MEDIUM] Stable Channel Update for Desktop: CVE-2024-2626
Stable Channel Update for Desktop
CVE-2024-2626: Out of bounds read in Swiftshader. Reported by Cassidy Kim(@cassidy6564) on 2023-11-22 [$4000][ 41493290 ] Medium CVE-2024-2627: Use after free in Canvas
Reported by Anonymous on 2024-01-21 [$3000][ 41487774 ] Medium CVE-2024-2628: Inappropriate implementation in Downloads
Severity: medium
Microsoft
Chromium: CVE-2024-2626 Out of bounds read in Swiftshader
vendor_msrc·2024-03-12·CVSS 6.5
CVE-2024-2626 [MEDIUM] Chromium: CVE-2024-2626 Out of bounds read in Swiftshader
Chromium: CVE-2024-2626 Out of bounds read in Swiftshader
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ:
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
123.0.2420.53
3/22/2024
123.0.6312.58/.59
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Micro
Debian
CVE-2024-2626: chromium - Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowe...
vendor_debian·2024·CVSS 6.5
CVE-2024-2626 [MEDIUM] CVE-2024-2626: chromium - Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowe...
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.58-1)
sid: resolved (fixed in 123.0.6312.58-1)
trixie: resolved (fixed in 123.0.6312.58-1)
OSV
CVE-2024-50228: In the Linux kernel, the following vulnerability has been resolved:
mm: shmem: fix data-race in shmem_getattr()
I got the following KCSAN report dur
osv·2024-11-09
CVE-2024-50228 CVE-2024-50228: In the Linux kernel, the following vulnerability has been resolved:
mm: shmem: fix data-race in shmem_getattr()
I got the following KCSAN report dur
In the Linux kernel, the following vulnerability has been resolved:
mm: shmem: fix data-race in shmem_getattr()
I got the following KCSAN report during syzbot testing:
BUG: KCSAN: data-race in generic_fillattr / inode_set_ctime_current
write to 0xffff888102eb3260 of 4 bytes by task 6565 on cpu 1:
inode_set_ctime_to_ts include/linux/fs.h:1638 [inline]
inode_set_ctime_current+0x169/0x1d0 fs/inode.c:2626
shmem_mknod+0x117/0x180 mm/shmem.c:3443
shmem_create+0x34/0x40 mm/shmem.c:3497
lookup_open fs/namei.c:3578 [inline]
open_last_lookups fs/namei.c:3647 [inline]
path_openat+0xdbc/0x1f00 fs/namei.c:3883
do_filp_open+0xf7/0x200 fs/namei.c:3913
do_sys_openat2+0xab/0x120 fs/open.c:1416
do_sys_open fs/open.c:1431 [inline]
__do_sys_openat fs/open.c:1447 [inline]
__se_sys_openat fs/open.c:1442 [in
GHSA
GHSA-4www-jw36-m87h: Out of bounds read in Swiftshader in Google Chrome prior to 123
ghsa_unreviewed·2024-03-20
CVE-2024-2626 [MEDIUM] CWE-125 GHSA-4www-jw36-m87h: Out of bounds read in Swiftshader in Google Chrome prior to 123
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2024-2626: Out of bounds read in Swiftshader in Google Chrome prior to 123
osv·2024-03-20·CVSS 6.5
CVE-2024-2626 [MEDIUM] CVE-2024-2626: Out of bounds read in Swiftshader in Google Chrome prior to 123
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_19.htmlhttps://issues.chromium.org/issues/40945098https://lists.fedoraproject.org/archives/list/[email protected]/message/2D3Z6CRRN4J3IUZPJZVURGMRBN6WFPTU/https://lists.fedoraproject.org/archives/list/[email protected]/message/6JINDYFB3MPH43ECTI72BV63K4RXSG22/https://lists.fedoraproject.org/archives/list/[email protected]/message/AQVVW4FLQDIJ2UABGXK2SMS5AUGT54FM/https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_19.htmlhttps://issues.chromium.org/issues/40945098https://lists.fedoraproject.org/archives/list/[email protected]/message/2D3Z6CRRN4J3IUZPJZVURGMRBN6WFPTU/https://lists.fedoraproject.org/archives/list/[email protected]/message/6JINDYFB3MPH43ECTI72BV63K4RXSG22/https://lists.fedoraproject.org/archives/list/[email protected]/message/AQVVW4FLQDIJ2UABGXK2SMS5AUGT54FM/
2024-03-20
Published